abound
abound2d ago
New

GRC Security Specialist

United KingdomUnited Kingdom·Londonfull-timemid
Security SpecialistSkilled Trades & Field Services
0 views0 saves0 applied

Quick Summary

Requirements Summary

1. Third-part

Technical Tools
Security SpecialistSkilled Trades & Field Services

We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer's unique financial situation.

We are formalising our security assurance function. We have technical controls and the engineering culture; what we need now is the governance layer that proves it - to our auditors, to our funders, and to our regulator.

You will be the delivery engine behind that. You will own the recurring assurance cycle end to end, run our third-party security programme, and be the person who turns evidence into something a due diligence team or a certification auditor can be satisfied by.

You will be responsible for building controls, gathering evidence, and challenging suppliers.

Responsibilities

~1 min read

- The ISO 27001 ISMS, which we are building towards certification. You will draft and maintain control documentation, populate the Statement of Applicability, gather evidence, coordinate the internal audit programme and be a primary point of contact for our external auditor. The Head of Security owns the framework, scope, and risk appetite.

- Policies and standards: you will draft, review and shepherd policies through approval, and track the review cycle.

- Incident response: you will maintain the IR plan and playbooks, facilitate post-incident reviews, track remediation actions, and support regulatory notification (ICO personal data breach reporting within 72 hours; FCA notification under Principle 11 / SUP 15.3).

- Business continuity and DR: you will maintain the documentation and the testing evidence.

- Secure development: you will help embed security requirements into the SDLC and support threat modelling sessions.

- Data protection: you will support RoPA maintenance, DPIA completion and DSAR handling alongside Legal.

- Run security due diligence on new suppliers, maintain initial questionnaire to risk sign-off, working with Procurement and Legal on security and data protection schedules.

- Maintain a supplier tiering model based on criticality and run the periodic re-assessment cycle for tiered suppliers: certification expiry, subprocessor changes, breach notifications, SLA performance.

- Maintain the supplier and outsourcing registers, including preparation for the FCA's material third party register under PS26/2 (rules in force 18 March 2027).

- Track concentration risk and exit plans for critical suppliers.

- Own our response to security due diligence from funders, banking partners, institutional investors, commercial partners and prospects.

- Build and maintain a reusable trust pack: answer library, security whitepaper, current certifications, pen test attestations, standard questionnaire pre-fills (SIG, CAIQ).

- Turn a 40-hour bespoke questionnaire response into a 4-hour one.

- Maintain the annual calendar of security activities and make sure each one happens, produces evidence, and closes its actions: penetration tests, access reviews, disaster recovery tests, tabletop exercises, policy reviews, supplier re-assessments, awareness training.

- Coordinate external penetration tests: scoping, vendor selection, scheduling, findings triage, remediation tracking, retest.

- Facilitate tabletop exercises, including scenario design and post-exercise action tracking.

- Maintain the information security risk register: run the assessment cycle, record treatment plans with named owners and dates, chase closure.

- Administer the policy exception and risk acceptance process, ensuring every exception is owned, time-bound and reviewed on expiry.

- Perform first-line control testing: sample-test where key controls operate as designed and retain the evidence.

- Produce security MI for the Head of Security to take to ExCo and the Risk Committee.

- Consolidate findings across sources — EDR, cloud security posture, SAST/DAST/SCA, secrets scanning, penetration tests — into a single view with agreed severity definitions and remediation SLAs.

- Triage, route and chase remediation with engineering teams; escalate ageing findings.

- Own the reporting on remediation performance.

- Run the awareness programme: induction, annual refresher, phishing simulation, role-based training for engineers, completion tracking.

- Coordinate pre-employment screening with People.

- Three or more years in an information security assurance, GRC or security compliance role, at least some of it in a regulated financial services environment or another environment with real external audit pressure.

- Hands-on experience of ISO 27001, whether operating an ISMS or taking one through certification.

- Demonstrable experience running third-party or vendor security assessments, and of responding to inbound security due diligence.

- Comfortable reading technical findings — an EDR vulnerability report, a penetration test finding, a cloud misconfiguration — and forming your own view on severity and real-world exploitability rather than passing the vendor's rating through unchanged.

- Clear, concise written English. Much of this role is writing things that external parties will judge us on.

- The confidence to chase a busy engineer, challenge a supplier's assertion, and tell us when an answer is not good enough.

- Experience of a cloud-native environment, ideally AWS.

- Experience of scaling a control framework as an organisation grows.

- Familiarity with UK operational resilience expectations (SYSC 15A) and outsourcing requirements (SYSC 8).

- Certifications such as CISM, CISA, ISO 27001 Lead Implementer or Lead Auditor, CRISC or CCSP. We care more about what you have done than what you hold.

Location & Eligibility

Where is the job
London, United Kingdom
Hybrid — some on-site time required
Who can apply
GB

Listing Details

Posted
September 25, 2026
First seen
September 26, 2026
Last seen
September 26, 2026

Posting Health

Days active
1
Repost count
0
Trust Level
60%
Scored at
September 27, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

aboundGRC Security Specialist